3 ms·
>But it isn't. It might be more secure because the average crypto holder is more savvy, but in terms of security properties, I wouldn't let my mom have a crypto
by cowtools 4y ago
>But it isn't. It might be more secure because the average crypto holder is more savvy, but in terms of security properties, I wouldn't let my mom have a crypto wallet, and without a direct wallet, I don't see how crypto has different properties than a bank (an entity making transactions on your behalf), the interface is the same, but the implementation details are different. No?
It's true to some extent that crypto users are more savvy than most, but I think cryptocurrency also has obviously superior security properties to the conventional banking system, technically speaking. In the conventional banking system, there are no "savvy" users because everyone is equally insecure no matter what. In the conventional banking systems it's all based on trust. Trust that the bank obeys the law, trust that law enforcement is not corrupt, etc. The security mechanisms of cryptocurrency are at most a superset of what you can do with the conventional banking systems. If you want to have a third party supervising transactions, you use 2-of-3 multisig for example (https://en.bitcoinwiki.org/wiki/Multisignature https://en.bitcoinwiki.org/wiki/Multisignature). If don't trust your family member to authorize payments without you, you use 2-of-2 multisig. If you don't trust yourself to not lose your keys, you back them up. If you want to limit your risk, you keep a small amount of cryptocurrency in a "hot" wallet.
Secondly, I don't think that the idea of a keypair is beyond the understanding of an average person. They effectively already know how to manage secrets in the current system: passwords, bank routing numbers, etc. It's just that the keypair is superior to these systems of authentication which often require you to reveal the secret itself to authenticate (credit card number), do not have enough entropy (4-digit-pin), are open source (E.g. security questions like "what's your mother's maiden name?"), or rely on other centralized systems (SMS-based 2FA). Even if you implemented some sort of "custodial keypair" that allowed you to transparently sign transactions without revealing your secret, that would be a major improvement over the current system which is based on (typically bad) secrets.
In many ways, the conventional banking system is more complicated than cryptocurrency, because the failures of cryptocurrencies are "solid" and well-defined (e.g. 51% attacks, MITM attacks, etc.) while the failures of the conventional banking system are "soft and fuzzy". For example, I was reading about a scam the other day wherein the attacker sends the victim a fake check, and asks them to cash out the money- this scam works because banks generally accept checks before validating them, allowing you to spend money that hasn't been validated yet and then charging you later. You might think this is obvious as a boomer, but as a zoomer who has never cashed a check before, this is not obvious at all.
And I'm not necessarily saying that cryptocurrency is the end-all-be-all of payment systems. There are superior systems like chaumian cash (https://taler.net/en/ https://taler.net/en/) but they require the permission of the existing banking system (which generally profits off providing services that surveil users and """fix""" the existing insecurity), so they haven't taken off.
I get the impression that regulation will never fix this because the nuances at hand will go over the head of any lawmaker who has merely accepted the insecurity of the status quo. I think that even if you get some libertarian or pro-cryptocurrency person in office which doesn't accept the current system, I highly doubt that they would make the right decision needed- it's more likely that any pro-cryptocurrency candidate is just going act in a way that benefits cryptocurrency owners.
Compare this to a topic like net neutrality. Even though I am a libertarian, I am more aligned with the democrats' views on net neutrality because of the obama administration's actions. Why? Not because the democrats are especially aligned to solve this problem, but merely they happened to have a good cabinet member or something that happened to understand the issue that election cycle and advise obama on that issue. It seems just as likely to me that the opposite might happen, albeit the democrats tend to be more pro-consumer in general. My point being that elected officials will not campaign on this because it is too nuanced, so solving this through politics is futile. It is better to just to improve cryptocurrency (or some other non-permissive technical solution) until it is competitive and forces the government/banking system to adapt (e.g. Project Hamilton).
P.S. I don't understand what you mean by a "direct wallet" here. A hardware wallet?
- hayst4ck 4y agoI am pretty crypto naive. My understanding is that a wallet is effectively a `private key => balance` and you can use the private key to sign transactions which are sent to a block chain where they are executed. So when I said "direct wallet" I meant the private key. My understanding is that many of the people who own crypto do so through a third party, so there is a layer of indirection. It's the difference between me having cash in hand (money in my pocket I can directly use) and me having cash in the bank (I tell my bank to send money to someone else and they execute the transaction on my behalf). My mom has downloaded ransomeware before, so from that perspective, I think crypto has worse security properties. If transactions are executed indirectly, the security properties are theoretically the same as executing transactions through a bank and you are back in a system of trust. Furthermore if a "cryptobank" gets hacked, that money is not retrievable, while theoretically in a system of pure fiat, the money might not be retrievable, but the value could be refunded at the cost of devaluing the currency as a whole. As far as behind the scenes implementation details go, a cryptographicly signed ledger with immutable history makes sense, but I also generally trust banks, much less so investment banks, and significantly less so the stock market.
- cowtools 4y ago>My understanding is that many of the people who own crypto do so through a third party, so there is a layer of indirection. It's the difference between me having cash in hand (money in my pocket I can directly use) and me having cash in the bank (I tell my bank to send money to someone else and they execute the transaction on my behalf). This is quite true, and it is likely the largest problem facing cryptocurrency today is this custodial use of it (besides all of the get-rich-quick schemes). But at its worst like this, cryptocurrency is a non-proprietary inter-bank payment method that prevents double-spending between banks. It is still superior to something like zelle, paypal, or SWIFT so long as the fees are lower. If cryptocurrency was the primary means of inter-bank transfer, then it would be trivial for anyone to start a new bank that could inter-network with the rest of the banking system, so I expect banks would be a lot more competitive (including on matters of privacy and security). >My mom has downloaded ransomeware before, so from that perspective, I think crypto has worse security properties. If transactions are executed indirectly, the security properties are theoretically the same as executing transactions through a bank and you are back in a system of trust. Furthermore if a "cryptobank" gets hacked, that money is not retrievable, while theoretically in a system of pure fiat, the money might not be retrievable, but Hmm. yes this is sort of a complicated subject. But I'll just re-iterate a point here which I may not have made as clear earlier: that cryptocurrency allows you to establish different levels of trust/risk through the means by which you manage your keys. A lot of older cryptocurrency users who don't practice good opsec will use a hardware token to sign transactions. Another example of what you could do is use a multi-signature system that would make it so that multiple keys are needed to move your funds (for example, they would have to hack at least X of Y devices in order to move funds), or simply have multiple wallets and limit the amount that you have in each one. And secondly, there are non-cryptocurrency ways of implementing different levels of trust/risk that you could integrate into the existing banking system, like chaumian cash or even just using cryptographic keypairs to authenticate transactions. In other words, losses of cryptocurrency due to theft or fraud are not always all-or-nothing. The difference between cryptocurrency and the conventional banking system is that you can decide your level of trust/risk you want to take before you do a transaction, which includes the use of a "cryptobank" (which could be secure but have historically been very scammy compared to conventional banks, see Mt Gox, Celcius, etc.). >the value could be refunded at the cost of devaluing the currency as a whole. I am not sure that it's a desirable property that the rest of society can bail out banks like you're describing. I think in an ideal situation you would have some sort of free-market-ish sort of way to balance the risk vs reward of different security practices, whether that's users voting with their dollar or with a middleman like rating agencies or insurance. And those incentives basically require the bank and its customers to lose money when they get robbed (maybe through some middleman like insurance). If you look at serious cryptocurrency exchanges like Kraken or Binance, there is a massive gap between "cryptobank gets hacked and loses some of their funds" and "cryptobank gets hacked and loses everything". They keep a lot of their funds on separate, air-gapped, offline systems, with the keys distributed between multiple people. Those aren't funds that you can steal with a normal cyber-attack: it would take pretty persistent social engineering akin to widespread corruption.